MAVEN · JULY 2026 · EARLY WARNING

veraPDF-validation XXE Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-36MM-W85J-3Q2JSeverity: HIGH

An XML External Entity Injection vulnerability in veraPDF-validation is under investigation. This vulnerability could allow a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery.

What happened

An XML External Entity Injection (XXE) vulnerability has been reported in veraPDF-validation, tracked as GHSA-36MM-W85J-3Q2J. This vulnerability appears to allow a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. The vulnerability affects all current versions of veraPDF-validation.

To assess your exposure, check if your systems are using veraPDF-validation. If so, it is recommended to upgrade to the latest version that includes the fix for this vulnerability. The primary source indicates that an upgrade is the recommended action to mitigate this risk.

For more detailed information, consult the primary source at https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-36mm-w85j-3q2j. The severity of this vulnerability is high, and it is crucial to take immediate action to protect your systems.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If verapdf-validation is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats